An AI-Powered Cyberattack That Cost Pennies Per Victim
A new report is drawing attention to just how cheap and scalable AI-powered cyberattacks have become. According to the findings, an AI system was used to compromise roughly 30 companies at a cost of about $4 per target, a figure that underscores how automation is collapsing the economics of cybercrime. For years, security researchers warned that artificial intelligence would eventually be turned into an offensive tool. This report suggests that shift is no longer theoretical.
What makes this case notable isn't just the number of victims or the low cost. It's the method. Instead of the traditional ransomware playbook, where attackers encrypt a victim's files and demand payment for a decryption key, this operation skipped encryption entirely. The attackers focused on stealing data and using it as leverage, a technique known as data-theft extortion.
From File Encryption to Automated Pressure Campaigns
Traditional ransomware relied on a fairly blunt mechanism: lock up a company's files, then demand payment to unlock them. That approach required attackers to maintain access long enough to encrypt large volumes of data, which gave defenders a window to detect and respond.
The operation described in this report bypasses that step. Rather than encrypting anything, the attackers reportedly used AI to build what's being called automated "pressure dossiers," compiled packages of stolen information designed to maximize a victim's incentive to pay. The AI system was also used to calculate ransom demands, suggesting the extortion amounts weren't set arbitrarily but generated based on factors the model assessed for each target.
This matters because it removes one of the biggest bottlenecks in ransomware operations: human labor. Reconnaissance, data collection, dossier creation, and even pricing decisions can now be handled by an automated system working across dozens of targets simultaneously. The report also references related developments in this space, including a model referred to as DeepSeek-V4-Pro, an autonomous agent called Hermes, security vulnerabilities tied to GitLab, and a ransomware group known as The Gentlemen, all pointing to a broader trend of AI tooling being woven into criminal operations rather than existing as isolated experiments.
For a wider view of how quickly these kinds of threats are stacking up, our recent ThreatsDay Roundup covering RCE flaws, a Samsung vulnerability, and the iCloud dispute shows that AI-assisted exploitation is just one piece of a much larger, fast-moving threat landscape that touches everything from mobile devices to cloud storage disputes.
Why the Cost Per Target Is the Real Story
A $4 cost per compromised company isn't just a headline number, it's a signal about scale. When the marginal cost of attacking one more organization approaches zero, the calculus for attackers changes entirely. Instead of carefully selecting high-value targets and investing significant time per victim, automated systems can attempt to breach large numbers of organizations at once, then let the economics sort out which ones are worth pursuing further.
This is a meaningful departure from how ransomware economics have traditionally worked. Human-operated intrusions require time for reconnaissance, lateral movement, and negotiation. An AI-driven pipeline can compress much of that timeline, generating extortion packages and demands with far less manual effort. Even if only a fraction of the 30 targeted companies ultimately paid or suffered serious harm, the low cost of the operation means the attackers didn't need a high success rate to make it worthwhile.
What This Means For You
If you run a business, or even manage sensitive data for a small team, this development is worth paying attention to regardless of your industry. Data-theft extortion doesn't require attackers to breach massive infrastructure or maintain long-term access. It requires finding exposed or poorly secured data and moving quickly. That means smaller companies, which often assume they're too insignificant to be targeted, are just as exposed as larger ones, especially now that automation lowers the cost of casting a wide net.
For individuals, the takeaway is more indirect but still relevant. As AI lowers the cost of data-theft campaigns, the odds that your personal information gets swept up in a breach involving a smaller vendor or service provider may increase over time. Extortion based on stolen data, rather than encrypted files, also means victims can't simply restore from backups and move on. Once data is copied, it's out of your control regardless of whether a ransom is paid.
Practical Steps Worth Taking
A few concrete actions can help reduce exposure to this kind of AI-powered cyberattack, whether you're protecting a business or your own accounts:
- Audit what sensitive data is stored where, and minimize what's kept in systems that don't strictly need it.
- Patch known vulnerabilities promptly, since automated attack tools are built to scan for exactly these gaps.
- Use strong, unique credentials and multi-factor authentication on any system that touches customer or financial data.
- Assume that low-cost, automated attacks will target smaller organizations too, not just high-profile enterprises.
As AI-powered cyberattacks become cheaper to run, the gap between well-defended organizations and everyone else is likely to widen. Staying informed about how these techniques evolve, and treating basic security hygiene as non-negotiable, remains one of the most effective ways to stay off the list of the next 30 companies.




